Unauthenticated Denial of Service in Milvus by Milvus-IO
CVE-2026-69111
Key Information:
Badges
What is CVE-2026-69111?
The vulnerability in Milvus allows remote attackers to exploit the unprotected /management/stop endpoint, leading to a denial of service. By sending a crafted HTTP GET request to the management server on port 9091, attackers can terminate service components such as the proxy, datanode, or querynode. This occurs due to a bypass of REST API authentication middleware when a 'role' parameter is supplied, enabling attackers to disrupt services without prior authentication.
Affected Version(s)
milvus 0 <= 2.6.22
milvus 0 <= 2.6.22
milvus 3.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
